Wednesday, September 9, 2026

BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials

BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing kit.

That goes far beyond traditional lures, enabling webcam capture, Microsoft Defender evasion, and targeted cryptocurrency credential theft.

New research from JUMPSEC provides rare source-level visibility into the operation after attackers mistakenly exposed JavaScript source maps on live infrastructure, allowing analysts to reconstruct the full attack lifecycle across Windows and macOS environments.

Unlike earlier campaigns that relied on simple spoofed meeting pages, this operation functions as a structured victim acquisition platform.

The attackers combine compromised industry contacts, particularly via Telegram, with tailored social engineering and wallet reconnaissance to selectively target high-value cryptocurrency users.

The exposed source code reveals fully developed Zoom and Microsoft Teams impersonation kits, with evidence suggesting a potential Google Meet variant referenced through infrastructure artifacts like “googie.us-gmeet.com.”

The phishing pages are built as single-page applications, capable of mimicking legitimate meeting workflows while silently executing reconnaissance scripts.

Once a victim accesses the link typically sent from a hijacked, trusted contact the platform initiates webcam access via WebRTC and streams video directly to attacker-controlled panels.

Simultaneously, the kit performs extensive browser-based cryptocurrency wallet fingerprinting using techniques such as EIP-6963 provider discovery, legacy window.ethereum probing, and enumeration of non-EVM wallets like Solana.

This reconnaissance enables operators to identify high-value targets before deploying malware, significantly increasing operational efficiency.

Pivoting across passive DNS, VirusTotal, urlscan.io and reverse DNS data expanded the investigation beyond the original infrastructure set, uncovering additional campaign infrastructure.

A founder announcing their Telegram account as compromised (Source : JUMPSEC).
A founder announcing their Telegram account as compromised (Source : JUMPSEC).

The social engineering component is particularly advanced. Victims are guided through a realistic meeting simulation where attackers deploy deepfake video overlays and scripted chat interactions.

Within seconds, victims are prompted to install a fake “Zoom SDK update,” which leverages a ClickFix-style clipboard hijacking technique. Even benign copy actions result in malicious PowerShell payloads being executed, initiating the infection chain.

JUMPSEC has obtained and analysed the source code behind an active BlueNoroff phishing kit used to impersonate Zoom and Microsoft Teams meetings. 

On Windows systems, the attack begins with a lightweight PowerShell loader that downloads and executes a VBScript implant identified as Trojan.NukeSped, a malware family historically associated with Lazarus operations.

BlueNoroff Fake Meeting Kit

The script establishes persistence, disables Microsoft Defender through exclusion policies, and performs system reconnaissance via WMI queries.

Aligns with BlueNoroff’s long-standing objective of funding North Korean state operations through attacks on financial institutions and Web3 platforms, as previously documented by CISA and Kaspersky in campaigns such as “GhostCall.”

The self-propagating system that continues to bring fresh victims in (Source : JUMPSEC).
The self-propagating system that continues to bring fresh victims in (Source : JUMPSEC).

It also enumerates browser extensions across Chromium-based and Firefox browsers to identify installed cryptocurrency wallets such as MetaMask.

Notably, the malware includes functionality to detect Telegram session artifacts stored in IndexedDB.

This enables attackers to hijack active Telegram sessions, reinforcing a self-propagating infection loop where compromised accounts are reused to target additional victims.

JUMPSEC observed this recursive model in multiple cases, consistent with previously reported BlueNoroff tradecraft.

OBS Virtual Cam for demo purposes (Source : JUMPSEC).
OBS Virtual Cam for demo purposes (Source : JUMPSEC).

The macOS variant follows a parallel execution model using shell scripts and Mach-O binaries. A fake Teams or Zoom installer acts as a decoy while background processes deploy a credential stealer.

Analysis of recovered samples, including “ZoomSDK.bin” variants on VirusTotal, shows rapid evolution from simple droppers to fully integrated stealers with LLVM-based obfuscation.

The stealer abuses the macOS security CLI to extract Keychain credentials, particularly Chrome-stored passwords, and exfiltrates them via hardcoded Telegram bot infrastructure.

Infrastructure analysis identified at least eleven initial command-and-control domains, with further expansion through passive DNS and OSINT techniques revealing a broader active network as of July 2026.

The reuse of modules across Zoom and Teams variants, including shared cryptographic execution functions, confirms a unified development pipeline.

This campaign underscores a shift in BlueNoroff operations toward scalable, intelligence-driven targeting that blends technical exploitation with human trust abuse.

By weaponizing legitimate relationships and integrating reconnaissance directly into phishing workflows, the group has significantly increased its success rate against high-value cryptocurrency stakeholders.

Indicators of Compromise

SHA256TypeSizeDetectionNotes
7a0b96f1063593a2e76f2f92ddfe091776a2ba63bc4f87f83dc5ebb675309d8dPowerShell516 B11/65Loader (zoom.05ukweb.uk variant)
180f797723bd65e82189eb1f737d39ce522614a182e2b46b51faeb49953a412fPowerShell514 B16/60 Trojan.SLoadLoader (weekly-up.online variant)
8889f1b67aea6896945506dae192326149f6c5db87e9b04fa08ac9a142a87775VBScript16,595 B21/62 Trojan.NukeSpedC2 implant (callsdk.online, +Telegram detection)
a86659dff126be72aff1d5e546baff735dcb7ed6ddd521737e7e3be8910c05f2VBScript13,676 B27/62 Trojan.SLoadC2 implant (weekly-up.online)
26bdad9189f6b28a90165c09ceed4386eff2fb352bea7fb78ebb164f28ebed28Shell script4,887 B0/60+ (FUD)Template dropper (parameterised)
163e4a72cbe392c073eddc60aee69dc1cf87ce492c375af74e923d75d8084683Shell script4,651 B0/62 (FUD)Deployed dropper (hardcoded weekly-up.online)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What Features Should AI SOC Have in 2026? A Complete Checklist Download the AI SOC Features Checklist

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware

A multi-stage malware operation that combines fake Google CAPTCHA...

SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

Austin, Texas / USA, September 9th, 2026, CyberNewswire Ninety-five percent...

Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs

Iran-linked cyberespionage group Mirage Kitten is targeting software engineers...

Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root

Two critical ArangoDB vulnerabilities can allow unauthenticated attackers to...

GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks

GoldFactory has expanded the evasion capabilities of its Gigabud...

Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems

Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker....

Related Articles

Recent News